Dependency cooldowns are unfair; we should use phased rollouts instead

18 points by quad


sunshowers

Cooldowns work against fast-acting supply-chain attacks. But they have an awkward property: they implicitly rely on someone else installing first.

This is not true. Cooldowns work based on security scanners being incentivized (successful detection gets them marketing) to detect and find these attacks. (Not a fan of calling them supply-chain attacks because open source software without a contract in place nothing to do with supply chains.)

7tehdt3cnw6kir6o

Dependency cooldowns would work against the present spate of supply chain attacks because they tend to be blunt smash and grabs that are detectable by automated scans within hours to days. They don't rely on someone else getting infected first.